Privacy policy

Last updated: 31 August 2026

This Privacy Policy explains how VAG Repair Center collects, uses, discloses and protects personal data when you visit www.vagrepaircenter.com, contact us, create an account, place an order or otherwise use our services.

1. Who controls your personal data

The data controller is:

Rok Sostar, operating under the name VAG Repair Center
Kurilovac 9
47280 Ozalj
Croatia
Email: sales@vagrepaircenter.com

2. Personal data we collect

Depending on how you interact with the store, we may collect:

  • Identity and contact data: name, email address, telephone number, billing address, shipping address and country.
  • Order and transaction data: products ordered, order number, amounts, discounts, currency, payment status, shipping method, tracking information, returns, refunds, warranty requests and related communications.
  • Payment data: payment method, payment provider and limited transaction information. Full payment-card details are handled by our payment providers and are not stored by us.
  • Account and communication data: account details, marketing preferences, messages sent through email, forms, Shopify Inbox or other customer-support channels.
  • Review data: review content and, if review invitations are enabled, information such as your name, email address and order reference that may be supplied to Trustpilot.
  • Device and usage data: IP address, browser and device type, operating system, pages viewed, referring page, approximate location, session identifiers, cookie identifiers, shopping-cart activity and consent choices.
  • Fraud and security data: technical signals and transaction information used to protect the store, customers and payment systems.

We collect this information directly from you, automatically from your device, and from service providers involved in payments, checkout, delivery, analytics, fraud prevention and customer support.

If information marked as required during checkout is not provided, we may be unable to process payment, complete the order, deliver products or provide requested support.

We process personal data for the following purposes:

Purpose GDPR legal basis
Displaying the store, maintaining a cart, creating an account, processing payment, fulfilling and delivering orders, handling returns, refunds, warranties and customer support Performance of a contract or steps requested before entering a contract (Article 6(1)(b))
Issuing invoices, maintaining legally required records, responding to authorities and complying with tax, accounting, consumer-protection and product-safety obligations Compliance with a legal obligation (Article 6(1)(c))
Protecting the store, detecting fraud, securing accounts, preventing abuse, maintaining evidence and establishing or defending legal claims Our legitimate interests in security, fraud prevention and protecting legal rights (Article 6(1)(f))
Improving store navigation, products and service performance using essential operational information Our legitimate interests in operating and improving the store (Article 6(1)(f)), provided those interests are not overridden by your rights
Using non-essential analytics cookies, Google Analytics, advertising cookies, personalised advertising or similar tracking Your consent (Article 6(1)(a)) where consent is required
Sending newsletters and promotional messages Your consent (Article 6(1)(a)), or another basis expressly permitted by applicable direct-marketing law; you can unsubscribe at any time
Measuring advertising conversions and campaign performance Consent where required; otherwise our legitimate interest in measuring advertising effectiveness, subject to applicable law and your choices
Requesting and publishing customer reviews Our legitimate interest in obtaining genuine service feedback where permitted, or consent where required

When processing is based on consent, you may withdraw consent at any time without affecting processing that occurred before withdrawal. When processing is based on legitimate interests, you may object as described in Section 10.

4. Cookies, analytics and advertising

We use cookies and similar technologies for:

  • Strictly necessary functions, including checkout, cart operation, security, fraud prevention, customer login and storing privacy choices.
  • Analytics, including Google Analytics 4, to understand visits, product views, cart activity and checkout performance.
  • Advertising and measurement, including Google Ads, to measure conversions and, where you consent, support personalised advertising and remarketing.
  • Functional services, such as customer messaging, reviews and delivery estimates.

Non-essential analytics and advertising technologies are controlled through the store's cookie banner. In regions where consent is required, these technologies are not activated until the relevant consent is given. You can later change or withdraw your choices through Cookie preferences in the store footer.

Google may receive device, browsing, conversion and order-related information. Where enabled and legally permitted, contact information used for enhanced conversion measurement may be transformed, such as by hashing, before transmission to Google. Google processes information according to its Privacy Policy.

Our Google Analytics event and user data retention setting is currently 14 months. Cookie lifetimes are separate and depend on the cookie and your browser or consent settings.

5. Shopify and Shopify Network Intelligence

The store is hosted by Shopify. Shopify processes personal data to provide storefront hosting, checkout, account, security, fraud-prevention, analytics, communication and related ecommerce services. The configured Shopify customer-data hosting location is the European Union, although Shopify and its subprocessors may process data in other countries as described below.

Shopify Network Intelligence is enabled. This means Shopify may use information from your interactions with this store together with information from your interactions with Shopify and other Shopify merchants to provide and improve services, including security, analytics, personalisation, advertising and other enhanced services. Other merchants do not receive direct access to this store's customer data.

Your privacy choices are transmitted to Shopify through Shopify's customer-privacy tools. You can learn more and exercise rights relating to Shopify's own processing through the Shopify Consumer Privacy Portal.

Where applicable, you can also opt out of processing that may be considered a sale, sharing or targeted advertising through our Your Privacy Choices / Data Sharing Opt-Out page.

6. Who receives personal data

We disclose only the information reasonably required for the relevant service. Recipients may include:

  • Shopify and its subprocessors for store hosting, checkout, accounts, email, messaging, security, analytics and ecommerce functionality.
  • Stripe for card-payment processing. Stripe's practices are described in the Stripe Privacy Policy.
  • PayPal when PayPal is selected or involved in a payment. PayPal may act as an independent controller for payment, regulatory and fraud-prevention purposes. See the PayPal Privacy Statement.
  • Google, including Google Analytics, Google Ads, Google Merchant Center and related services, for analytics, advertising, conversion measurement and product promotion.
  • Trustpilot, if review invitations or Trustpilot review features are used. Trustpilot may receive contact and order-reference information, and reviews submitted to Trustpilot may be public. See the Trustpilot Privacy Policy.
  • Shopify Inbox and email services for customer communications and marketing messages requested by you.
  • Delivery-estimate, logistics, postal, courier, fulfillment and customs providers where necessary to show delivery information or deliver an order. Delivery-estimate technologies currently include Deliverr/Flexport components. See the Flexport Privacy Policy.
  • Professional advisers, insurers, payment-dispute services and IT/security providers where reasonably necessary.
  • Courts, regulators, tax authorities, customs authorities, law enforcement or other public bodies where disclosure is required or permitted by law.
  • A purchaser or successor if the store or its assets are reorganised, sold or transferred, subject to appropriate confidentiality and legal safeguards.

Some providers, particularly payment providers, Google, Shopify and Trustpilot, may act as independent controllers for certain processing and apply their own privacy notices.

We do not sell personal data for money. However, some advertising and Shopify Network Intelligence activities may be legally defined as a “sale,” “sharing” or “targeted advertising” under certain United States privacy laws. Where those laws apply, you may use the opt-out methods described in Sections 4, 5 and 11.

7. International transfers

We are based in Croatia and primarily administer the store from the European Economic Area (EEA). Some service providers and their subprocessors operate in Canada, the United States and other countries outside the EEA. Worldwide delivery can also require shipping details to be processed by carriers and customs authorities in destination or transit countries.

Where GDPR applies and personal data is transferred outside the EEA, the transfer is protected by an available lawful mechanism appropriate to the recipient and transfer, such as an adequacy decision, the European Commission's Standard Contractual Clauses, participation in the EU–US Data Privacy Framework where applicable, or another safeguard permitted by data-protection law. Information about the safeguards relevant to a particular transfer can be requested from us using the contact details in Section 14.

8. How long we keep personal data

We retain personal data only for as long as required for the purpose for which it was collected, subject to legal obligations and legitimate needs:

  • Order, invoice, payment and tax records: for the period required by applicable Croatian tax and accounting law and as needed for audits or legal claims.
  • Delivery, return, refund and warranty records: until the matter is completed and for the period in which related legal or consumer claims may be made.
  • Customer accounts: while the account is active and until deletion is requested, except for information that must be retained for orders, security or legal obligations.
  • Customer-service communications: for as long as needed to resolve the request and any related complaint or legal claim.
  • Marketing information: until consent is withdrawn or you unsubscribe. We may keep minimal suppression information so that we continue to respect the opt-out.
  • Analytics event and user data: up to 14 months in Google Analytics, unless aggregated or anonymised earlier.
  • Consent and privacy-choice records: for as long as reasonably necessary to demonstrate and respect your choices and meet legal obligations.
  • Security and fraud information: for as long as reasonably necessary to investigate incidents, prevent repeat abuse and establish or defend legal claims.

Providers may retain information under their own policies when acting as independent controllers. When retention is no longer justified, information is deleted, anonymised or securely restricted unless continued storage is legally required.

9. Automated processing and profiling

Payment processors, Shopify and fraud-prevention providers may use automated signals to authorise payments, identify suspicious transactions or protect accounts. Google and Shopify may use browsing and purchase signals to measure advertising or personalise services where permitted by your choices.

We do not independently make decisions based solely on automated processing that produce legal or similarly significant effects on you. A payment or fraud provider may make its own automated decision under its own privacy notice. You may contact us if you believe an automated decision has incorrectly affected an order.

10. Your rights under GDPR

Where GDPR applies, you may have the right to:

  • obtain confirmation and access to your personal data;
  • correct inaccurate or incomplete data;
  • request deletion of data in applicable circumstances;
  • restrict processing in applicable circumstances;
  • receive data you supplied in a structured, commonly used and machine-readable format and transmit it to another controller where the right to portability applies;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing, including related profiling;
  • withdraw consent at any time; and
  • lodge a complaint with a supervisory authority.

Send requests to sales@vagrepaircenter.com. We may request information reasonably necessary to verify your identity. We normally respond within one month where GDPR applies. This period may be extended by up to two additional months for complex or numerous requests, in which case we will notify you.

These rights are not absolute. For example, we may retain information needed to comply with tax or accounting law, complete an order, prevent fraud or establish or defend legal claims.

You may lodge a complaint with the Croatian supervisory authority:

Croatian Personal Data Protection Agency (AZOP)
Ulica Metela Ožegovića 16
10000 Zagreb, Croatia
Email: azop@azop.hr
Website: https://azop.hr/

If you live elsewhere, you may also contact the competent data-protection authority in your country where permitted by applicable law.

11. Additional rights in the United States and other regions

Depending on your place of residence and whether the relevant law applies to our activity, you may have additional rights to know, access, correct or delete personal information, obtain a portable copy, and opt out of a sale, sharing, targeted advertising or certain profiling.

We will not discriminate against you for exercising an applicable privacy right. Requests may be sent to sales@vagrepaircenter.com. Where available, use our Your Privacy Choices / Data Sharing Opt-Out page. Supported Global Privacy Control signals are also applied by Shopify where configured and required.

12. Security

We use reasonable technical and organisational measures intended to protect personal data, including Shopify's secure infrastructure, encrypted connections, access controls and limiting access to people and providers who need the information for the purposes described above.

No internet transmission or storage system can be guaranteed completely secure. Please do not send full payment-card details or other unnecessary sensitive information by email or chat.

13. Children

The store is not directed to children, and we do not knowingly collect personal data from children who cannot lawfully provide it or enter into a purchase. Consent-based online services offered directly to a child in Croatia generally require parental authorisation when the child is under 16; different rules may apply in other countries.

If you are a parent or guardian and believe a child has provided personal data improperly, contact us so that we can investigate and delete it where appropriate.

14. Contact us

For questions, complaints or privacy-rights requests, contact:

VAG Repair Center — Rok Sostar
Kurilovac 9
47280 Ozalj
Croatia
Email: sales@vagrepaircenter.com

15. Changes to this policy

We may update this Privacy Policy to reflect changes in the store, service providers, technology or applicable law. The current version will be published on this page with an updated date. If a change materially affects your rights or how we use personal data, we will provide additional notice where required.